Re: NTFS permissions?



Thanks.

It is how you suggested. The creator owner is from directory and the
username of the creator is shown in the files properties/security tab.

It was actually a very funny situation since the user was able to edit and
even delete the file but not rename it :) The problem was solved by adding
creator/owner rights to write to the directory holdin the file.

Will



"Harry Johnston" <harry@xxxxxxxxxxxxxxxxxx> kirjoitti
viestissä:epdfX%23dhHHA.1240@xxxxxxxxxxxxxxxxxxxxxxx
William Stokes wrote:

I read from 2003R2 server help that NTFS permissions are cumulative. So
does this mean that if user has a read access to a file via Domain Users
Group (to which he is a member) and Full Controll because of Creator
Owner rights (which he is) the result is that this user has full controll
to the file?

Yes and no. NTFS permissions are cumulative as you describe. However
CREATOR OWNER doesn't count directly towards a user's permissions, it is
only used in inheritance.

So if the permissions on the file say

Domain Users:R
CREATOR OWNER:F

the user will have read access. If the permissions were inherited from a
directory, CREATOR OWNER should have been automatically replaced by the
username, so it would look like

Domain Users:R
username:F

and the user would have full acccess.

I've been testing this scenario and it happens that the user seems to
have full controll while viewing Effective Access tab in the file
properties but he cannot rename the file.

You should also note that you need write access to the folder as well as
the file in order to rename a file.

Harry.


.



Relevant Pages

  • Re: Permission to Copy Files to Server Folder But Not Edit Them
    ... not need creator owner permissions dues to the user either already having ... needed permissions for his user account or via group membership. ... Group Policy to remove the security tab from folder/file properties for ... Select folder only in the apply onto box and hit OK. ...
    (microsoft.public.security)
  • Re: Allow saves and reads but not edits
    ... I had to give Domain Users List and Read ... > are seeing in the NTFS permissions editor. ... > and due to temp files the Creator Owner Modify ...
    (microsoft.public.win2000.security)
  • Re: Allow saves and reads but not edits
    ... I had to give Domain Users List and Read ... >> are seeing in the NTFS permissions editor. ... >> and due to temp files the Creator Owner Modify ...
    (microsoft.public.win2000.security)
  • Creator Owner Permissions
    ... I have a W2K SP4 server. ... NTFS permissions to either of the two volumes ... I cannot grant Creator Owner ...
    (microsoft.public.win2000.security)
  • Strange NTFS permission problems
    ... I was going through the procedures for setting up IIS 5 with minimum NTFS ... I not only can't apply Creator Owner full access rights on the root drive, ...
    (microsoft.public.windowsxp.security_admin)